PT-2002-2462 · Alt N Technologies · Mdaemon

Published

2002-12-31

·

Updated

2017-07-11

·

CVE-2002-1740

CVSS v2.0

2.1

Low

VectorAV:L/AC:L/Au:N/C:N/I:P/A:N
Name of the Vulnerable Software and Affected Versions Alt-N Technologies MDaemon versions 5.0.5.0 and earlier
Description The issue is related to a buffer overflow in WorldClient.cgi, part of WorldClient in Alt-N Technologies MDaemon. This occurs when a local user provides a long folder name via the NewFolder parameter, allowing the execution of arbitrary code.
Recommendations For versions 5.0.5.0 and earlier, consider restricting access to the WorldClient.cgi until a fix is available, and avoid using long folder names via the NewFolder parameter to minimize the risk of exploitation.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Related Identifiers

CVE-2002-1740

Affected Products

Mdaemon